Liferay Portal and Liferay DXP allows arbitrary injection via the site name
Moderate severity
GitHub Reviewed
Published
Apr 26, 2022
to the GitHub Advisory Database
•
Updated Jul 14, 2025
Description
Published by the National Vulnerability Database
Apr 25, 2022
Published to the GitHub Advisory Database
Apr 26, 2022
Last updated
Jul 14, 2025
Reviewed
Jul 14, 2025
Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration before 2.0.4 in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the site name.
References